IEC 15408 Information Technology Security Evaluation Criteria (Common Criteria)

    IEC 15408 Introduction

    As more digital systems are deployed, IT product security is now a critical concern within the government, defence, finance, healthcare, and even commercial systems. The difference in security design and implementation may cause vulnerability unless it is correctly evaluated. IEC 15408 offers a formal and standardized framework for defining security goals, defining threats, and determining whether IT products are sufficient to cope with the threats. The standard allows a clear assessment of security, global confidence, and confidence in certified IT products.

    Read more

    Get Certified IEC 15408 for Trusted IT Security

    The IEC 15408 certification shows that an IT product or system has been evaluated with respect to security in a strict, independent manner. Certification improves market acceptance, regulatory needs, and procurement needs, as well as the user confidence in the product security. Adherence to IEC 15408 is generally mandatory in government and high-security installations and supports cross-border acceptance by providing Common Criteria recognition agreements.

    IEC 15408 Requirements and Evaluation Criteria

    Security Assurance Requirements (SARs)Security measures that guarantee the proper execution of security functions.
    Protection Profiles (PPs)There are standard security requirements for a given product type.
    Security Targets (STs)Product-specific security claims and implementation details
    Evaluation Assurance Levels (EALs)Graded levels of evaluation depth and rigor
    Vulnerability AnalysisAssessment of resistance to known and potential attacks
    DocumentationComprehensive security and design documentation

    Scope of IEC 15408

    • IEC 15408 applies to those IT products and systems that need a formal security assessment. 
    • Encompasses operating systems, databases, smart cards, network devices, cryptographic modules, biometric systems, and embedded systems. 
    • Both the functional security requirements and the assurance activities have been defined in the standard, which allows it to be evaluated over a large variety of technologies and security requirements. 
    • Promotes the global standardization of IT security tests and certification.

    IEC 15408 Equipment and Sample Preparation

    Evaluation TargetClearly define the IT product or system under evaluation
    Documentation PreparationDevelop security targets, design documents, and guidance materials
    Test EnvironmentConfigure representative hardware and software environments
    Configuration ControlEnsure the evaluated configuration matches the deployed configuration

    Applications of IEC 15408

    • Security certification of government and defense IT systems, financial and banking platforms, smart cards and secure elements, network infrastructure devices, identity and access management solutions, and critical infrastructure control systems is all done using IEC 15408. 
    • Helps in procurement decision making, regulatory, and implementation of trusted IT products in high-risk environments.

    IEC 15408 Common Challenges and Troubleshooting

    Common challenges encompass incomplete protection documentation, doubtful safety targets, and mismatches between implemented functionality and claimed safety requirements. High evaluation expenses and extended timelines can also be a concern. These problems are mitigated by using early alignment with protection profiles, a clear definition of security targets, and close coordination with permitted evaluation laboratories during the development lifecycle.

    Read more

    IEC 15408 Evaluation Process and Data Collection

    The process of IEC 15408 starts by establishing security goals and the protection profiles that should be used. Functional testing, penetration testing, and evaluation of design documentation, development, and lifecycle controls are conducted by evaluators. Collected data involves the test results, vulnerability results, evidence of configuration, and assurance documentation. Any of the findings is reviewed to the extent of meeting the chosen Evaluation Assurance Level.

    IEC 15408 Analysis Results and Interpretation

    The results of IEC 15408 show that the IT product either meets its claimed security claims at its specified assurance level or does not. Effective testing would prove that security functions are well implemented, tested, and resistant to specified levels of threats. Lack of compliance causes gaps during design, implementation, or assurance practices, which must be remedied and reassessed.

    Read more

    IEC 15408 Problem & Solution

    Problem: There is no trust between organizations and the security assurances of IT products in sensitive settings.

    Solution: IEC 15408 is an internationally recognized assessment model that confirms security functionality and assurance, and thus certified IT products can be deployed in trusted situations.

    FAQ

    Where can I get the iec 15408 tested?
    You can share your iec 15408 testing requirements with MaTestLab. MaTestLab has a vast network of material testing laboratories, spread across the USA and Canada. We support your all material testing needs ranging from specific iec 15408 test to various testing techniques.
    Please contact us for a detailed quote for your iec 15408 testing needs. Cost incurred to carry out different iec 15408 testing methodology depends on the type of raw material; number of samples, coupons, or specimens; test conditions, turn around time etc. Costs of some ASTM testing methods start from $100 and the final value depends upon the factors listed above. Please contact us for the best and latest prices.
    The required number of samples or specimens should comply with the procedure given in the iec 15408 standard. However, the MaTestLab operations team can assist you for your special requirements once you share your testing details with us.
    MaTestLab has a vast testing laboratory network, hence we bring you the best testing facilities in a cost-effective way. We offer considerable discounts (15-20%) to our returning customers based on test volume and frequency.
    The turnaround time for iec 15408 test methodology depends upon the test procedure mentioned in the standard test document. However, we at MaTestLab understand your research requirements and hence try to get your test completed within the least possible time.
    Davis Scott
    About Author
    Davis Scott
    Davis Scott is an Electrical and Electronics Engineer specializing in multidisciplinary validation, quality assurance, and comprehensive electro-mechanical testing.
    Testimonials
    Real results
    Engineers trust us with what matters most
    Start Your Testing
    Project Today
    Define your requirements and get access to
    specialized laboratories ready to deliver results
    Partners with us
    Clients
    Vendors
    Process for testing
    • STEP 01

      You share your testing requirements

    • STEP 02

      You share your sample(s)

    • STEP 03

      We deliver your test reports

    Get your testing done

    Let us known your testing requirements and we will be right back with a solution.

      Let us root for each other. Collaborate to grow, expand, and accelerate our businesses.

      Partner with us

        Contact Us

        Discover more from MaTestLab

        Subscribe now to keep reading and get access to the full archive.

        Continue reading